RHSA-2020:5533HighCVSS 7.7

Red Hat Security Advisory: Red Hat Single Sign-On 7.4.4 security update

Published
December 15, 2020
Last Modified
August 4, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2020-10695 — containers/redhat-sso-7: /etc/passwd is given incorrect privileges CVE-2020-13822 — nodejs-elliptic: improper encoding checks allows a certain degree of signature malleability in ECDSA signatures CVE-2020-25638 — hibernate-core: SQL injection vulnerability when both hibernate.use_sql_comments and JPQL String literals are used CVE-2020-25649 — jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE) CVE-2020-27826 — keycloak: Account REST API can update user metadata attributes

🎯 Affected products1

  • Text-Only RHSSO

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update). Workaround: Set hibernate.use_sql_comments to false, which is the default value, or use named parameters instead of literals. Please refer to details in https://docs.jboss.org/hibernate/orm/5.4/userguide/html_single/Hibernate_User_Guide.html#configurations-logging and https://docs.jboss.org/hibernate/orm/5.4/userguide/html_single/Hibernate_User_Guide.html#sql-query-parameters. Workaround: There is currently no known mitigation for this flaw.

🔗 References (8)